Dear Customer,

We are pleased that you are interested to be informed about your data protection. We would like to give you an easily understandable overview of our data protection process.

Our goal is to provide you with an amazing customer experience that also means that you can always trust us, that we are always transparent and honest to you. Your trust in our product is the reason why we can provide you with an amazing customer experience. We would like to thank you for this cooperation.

Who we are

We are Mustard Indian Kitchen and we love to protect customer data.

While visiting our website or apps, registering or placing orders, you agree to this privacy policy.

As data controller, we determine how we process your personal data, for what purposes and by what means. While we are required by law to provide you with all of the following information, we do so primarily out of the belief that a partnership should always be honest.

As data controller we are responsible that all our processing activities are in accordance with legal requirements but also you may reasonably expect these processing of your personal data.

If you have any questions about data protection at Mustard Indian Kitchen, you can also contact our data protection officer at any time by sending an email to support@arrowheadit.com

We will continue to be your point of contact if you have any questions about data protection.

Privacy is your right and you have the choice

As a customer you have the choice which information you would like to share with us. Of course we need some information for the fulfillment of our contract. However, this does not always require all the data which you can make available to us.

You can take the following steps to disclose less information about yourself:

Advertising: If you do not want to receive newsletters from us, you can delete your account at any time. In this case, we will not be able to send you any cool offers.

No data sharing: If you don't want to share any information with us at all, that's a shame. In this case we can't convince you how great our products are.

You can also make use of the following rights at any time:

Process of Data Storage

You can create your account only with your email address. But to place an order you have to provide your details (Name, Mobile No and Address) for the delivery purpose.

Process of Reset Password

If you forgot your account password then you can reset it by your email address.

Right to access

You have the right access you data any time from your profile.

Right to rectification

If you notice that stored data is incorrect, you can always update it.

Right to erasure

You can delete your account any time and we will have no record of you except purchase history after deletion.

Right to object to the processing of your data

You can revoke your consent at any time or object to the further processing of your data. This also includes objecting to our processing, which we process without your consent but based on our legitimate interest. This applies, for example, to direct marketing. You can object to receiving further newsletters at any time.

If you do not agree with one of our processing purposes based on our legitimate interest or wish to object to it, you may object to the processing at any time on grounds relating to his or her particular situation. Please write an email to support@arrowheadit.com. In this case we will review the processing activity again and either stop processing your data for this purpose or explain to you our reasons worth protecting and why we will continue with the processing.

Right of complaint

If you believe that we have done something wrong with your personal data or your rights, you can complain to the appropriate supervisory authority at any time.

To exercise your rights, you can contact support@arrowheadit.com at any time.

What data we process

In the following description of our processing activities, we refer in each case to categories of personal data. A category includes several personal data, which are usually processed together for the purposes.

Personal data is information that can identify you or even make you identifiable.

We generally process the following categories of personal data for the following reasons:

Contact Information:

Name, address, telephone number, email address and postal address.

Reason:

We collect this data because we need to delivery the order to exact location

Location data:

Address, Postcode, City, Country, Longitude, Latitude

Reason:

We need these data to be able to deliver your orders. We create the longitude and latitude automatically in order to be able to process your delivery address.

Profile data (master data):

Name, email address, password, telephone number, delivery addresses

Reason:

This data is your master data, which we absolutely need for our services. Without an email address / telephone number and a password, you cannot create a profile. Together with your name, this is your master data. We need your age to ensure that you are not a minor.

Device information and access data:

Device ID, device identification, operating system and corresponding version, time of access, configuration settings, information on Internet connection (IP address)

Reason:

With each access this information is stored by us for technical reasons. We also use parts of this information to detect suspicious behaviour at an early stage and to avert damage.

Order information:

Order history, invoices, order ID, delivery address, successful orders and cancelled orders

Reason:

Each time you place an order, this information will be added to your profile. You can view all this information in your profile at any time. The information should give you an overview of your own interests and previous orders. We will also use the same information to improve our services. In addition, we will anonymize this information when you request a deletion or when your profile becomes inactive in order to continue to use this information in an anonymized form to optimize our services.

Communication data

Name, email address, telephone number, device ID

Reason:

If you would like to receive a newsletter, an SMS or an in-app push notification from us, we need certain information to send you the messages. Instead of addressing you with "Hey You", we find it more customer friendly to address you with your name. This category of personal information is also used by us to contact you, for example, if a product cannot be delivered and we want to offer you an alternative instead.

Payment information:

Payment method

Reason:

We need this information to track your payments and assign them to the orders you have placed.

Delivery information:

Name, delivery address, phone number, order ID

Reason:

In accordance with the principle of data minimization, we only provide our riders and restaurants with the information that they need from you to prepare and deliver your order.

For which purposes we process data

We process your personal data only in accordance with the strict legal requirements. We pay particular attention to the fact that all principles for the processing of personal data are taken into account. The Delivery Hero Group pays great attention to transparency. Therefore, we only process your data if this is lawful and you can reasonably expect it to be processed. If, in the course of our evaluation, we come to the conclusion that the processing cannot reasonably be expected, we will only carry out the processing with your express consent.

ACCOUNT CREATION

In order to be able to offer you our services, the processing of your personal data is essential. Much of this data you transmit to us and other parts of the data we collect automatically when using our platforms. Nevertheless, we endeavour to keep the amount of data as small as possible. You can help us by only sharing necessary data with us that we need to fulfill our contractual obligations.

When creating a customer account you will be asked to enter your master data. This is absolutely necessary, as we cannot create a customer profile without this data. Your email address is particularly important, as we can use this information to identify you in our system the next time you want to log in again. Furthermore, we would like to ask you to choose your password carefully. Do not use the same password on multiple websites. Your password should also be at least 8 characters long, at least one lowercase letter, one uppercase letter, one special character (!?#,%& etc.) and one digit. Please don’t share neither your password nor your email address with anyone else.

Categories of personal data:

Profile data (master data)

Device information and access data

Legal basis:

Performance of contract

Login

If you already have an existing customer account, you will need to enter your email address and password to log in. If we detect irregularities during registration, such as entering the wrong password several times, we will take appropriate measures to prevent damage to you and us.

PAYMENT METHODS

In order to make the ordering process even more convenient for you, we offer online payment (Paypal). We don't offer to save payment method or any kind of payment data except transaction info.

Categories of personal data:

Cookies

In order to make the visit of our website/app attractive and to enable the use of certain functions, we use so-called cookies on various pages. These are small text files that are stored on your device. Some of the cookies we use are deleted after the end of the browser session, i.e. after closing your browser (so-called session cookies). Other cookies remain on your device and allow us or our affiliate to recognize your browser on your next visit (persistent cookies).

FRAUD PREVENTION AND SECURITY OF OUR PLATFORM

In order to protect our customers and our platform from possible attacks, we continuously monitor the activities on our website for all visitors. To this end, we use various technical measures to ensure that suspicious behavior patterns are detected at an early stage and prevented in good time. To achieve this goal, several monitoring mechanisms run in parallel and prevent potential attackers from accessing our website at all.

The decision-making process is automated and can have a legal effect on the person concerned or affect them in a similar way. If automated decision making leads to a negative result for you and you do not agree with this, you can contact us at support@arrowheadit.com. In this case, we will individually assess the circumstances of your case.

Categories of personal data:

Device information and access data

Contact information

Order information

Voucher information

How long we store your data

We generally delete your data after the purpose has been fulfilled. The exact deletion rules are defined in our regional deletion concepts. Different deletion rules apply depending on the purpose of the processing. Within our deletion concepts we have defined various data classes and assigned rule deletion periods to them. The data collected is marked with a deletion rule. When the retention period is met, the stored data will be deleted accordingly.

We will delete your personal data either if you wish and let us know or if your account is inactive for one year, we will also delete your account. Before this happens, you will receive a separate notification from us to the email address registered in your user account.

Right of modification

We reserve the right to change this data protection declaration in compliance with the statutory provisions. We will inform you of any significant changes, such as changes of purpose or new purposes of processing.

Last update: June 2023